A.7.8 Physical
Equipment siting and protection
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (25)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PE-18mostlyaligns with — Both controls focus on physically locating equipment to reduce exposure to unauthorized observation, environmental hazards, and interference.
- PE-18mostlycovers — A.7.8's siting/protection requirement to reduce physical/environmental/unauthorized-access risks accounts for the bulk of PE-18's positioning mandate; residual exists in PE-18's explicit threat-parameter selection and system-component (vs. generic equipment) framing.
- PE-19mostlyaligns with — Both address countermeasures against information leakage from electromagnetic emanations and other physical emanation risks.
- PE-14partialaligns with — Both require ongoing monitoring of environmental conditions such as temperature and humidity that affect system operation.
- PE-14partialcovers — A.7.8's siting and protection measures address some environmental threats that PE-14's temperature/humidity monitoring and maintenance directly implement, but A.7.8 is far broader (physical access, fire, water, power, etc.) while leaving the specific continuous monitoring and parameter-maintenance requirements of PE-14 mostly uncovered.
- PE-15partialaligns with — Both seek to protect equipment from water damage and related environmental hazards through siting and protective measures.
- PE-3partialaligns with — Both emphasize physical placement and access restrictions to limit unauthorized entry to areas containing sensitive equipment.
- PE-3partialcovers — A.7.8's siting/protection measures address a slice of PE-3's physical access enforcement (especially ingress/egress controls and facility protection), but leave the bulk of authorization verification, audit logging, and inner-area controls uncovered.
- PE-9partialaligns with — Both require safeguards for power and communications cabling against environmental and interference threats.
- PE-9partialcovers — A.7.8's broad siting/protection of equipment against physical/environmental threats and unauthorized access addresses a slice of PE-9's specific power-equipment-and-cabling protection requirement, but leaves the bulk of the target's power-specific focus and cabling details uncovered.
- PE-15covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PE-19covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Aligned NIST CSF 2.0 outcomes (14)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.AA-06mostlycovers — By requiring equipment siting and physical separation to prevent unauthorized access, the ISO control satisfies the CSF outcome of managing, monitoring, and enforcing physical access to assets commensurate with risk.
- PR.IR-02mostlycovers — The ISO control's focus on shielding equipment from environmental threats such as fire, water, dust, vibration, and electromagnetic interference directly fulfills the CSF outcome of protecting technology assets from environmental threats.
- DE.CM-02partialaligns with — The ISO guidance to monitor environmental conditions like temperature and humidity aligns with the CSF outcome of monitoring the physical environment to detect potentially adverse events.
- PR.DS-01partialaligns with — Placing sensitive-data equipment to avoid visual eavesdropping and electromagnetic emanation contributes to the CSF outcome of protecting the confidentiality of data-at-rest.
- PR.IR-01partialaligns with — Positioning and physically separating equipment to reduce unauthorized logical or physical access supports the CSF outcome of protecting networks and environments from unauthorized logical access and usage.
- DE.CM-02implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.DS-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.IR-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Related weaknesses / CWE (11)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1263prevents — Equipment siting helps reduce exposure but is secondary to access-control measures.
- CWE-1278mitigates — Proper siting and protection of equipment can reduce exposure to imaging tools.
- CWE-1300mitigates — Proper siting and protection of equipment can reduce observable emissions.
- CWE-1319mitigates — Equipment siting and protection can reduce exposure to EM sources but does not specifically target fault-injection vectors.
- CWE-1384prevents — Requires proper siting and protection of equipment against environmental hazards.
- CWE-200prevents — Positioning equipment and shielding emanations reduce the chance that an attacker can observe or capture sensitive data through physical proximity or side-channel leakage.
- CWE-284mitigates — Siting equipment to limit unnecessary access and physically separating managed from unmanaged facilities directly restricts unauthorized actors from reaching protected resources.
- CWE-552mitigates — Placing equipment away from public or shared areas and segregating organizational facilities lowers the exposure of files, devices, or directories to external parties.
- CWE-732mitigates — Physical placement and environmental controls complement permission settings by reducing the opportunity for an attacker who gains physical proximity to exploit overly permissive resource assignments.
Mitigated MITRE ATT&CK techniques (66)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1005prevents — A.7.8 siting/protection and emanation controls can stop some physical or side-channel access vectors that enable local data searches on managed equipment, but do not block command-line, automated, or logical searches on the vast majority of the technique's platforms and methods.
- T1052detects — A.7.8 requires monitoring environmental conditions (e) and siting/protection against unauthorized access and physical threats (a,c), which can surface anomalous device introductions or use in protected areas, but does not mandate technical detection of data copies to removable media or exfiltration events themselves.
- T1052prevents — A.7.8 siting/protection guidelines (a,b,c,h,i) directly constrain physical-medium insertion and exfiltration paths in air-gapped or separated environments, but leave many user-introduced-device and non-facility vectors untouched.
- T1052.001detects — A.7.8 requires monitoring environmental conditions and applying physical protections that can surface anomalous USB device activity or unauthorized physical access in protected areas, but this is indirect, scope-limited to certain environments, and does not broadly detect the exfiltration technique itself.
- T1052.001prevents — A.7.8 siting/protection (esp. a, b, c, h, i) directly constrains physical USB device introduction and use in sensitive areas, blocking the air-gapped exfiltration path in the technique's own description; partial because it does not reach every USB exfil scenario (e.g. authorized devices on managed systems).
- T1091prevents — Restricting physical access and siting of equipment limits the chance of malware being spread via removable media left in or near systems.
- T1125prevents — A.7.8 siting/protection of equipment and physical separation of facilities can prevent some physical unauthorized access to peripherals like webcams in managed environments, but does not stop malware/scripts from using OS APIs to activate already-present integrated cameras on Linux/macOS/Windows endpoints.
- T1200prevents — Physical placement and access restrictions reduce the opportunity for an adversary to introduce unauthorized hardware into the environment.
- T1200detects — A.7.8 requires monitoring environmental conditions (e) plus siting/protection against unauthorized physical access and threats like theft/vandalism, which can surface some hardware additions as anomalies or events but does not systematically detect all vectors (e.g. DMA devices, keystroke injectors, or passive taps once introduced).
- T1219.003prevents — A.7.8 siting/protection guidelines (esp. a, b, c, g, h, i) directly constrain physical installation and electromagnetic leakage of remote-access KVM hardware, stopping the technique from being introduced in many environments; partial because the control is silent on post-compromise software bypass or use of already-permitted peripherals.
- T1485recovers — A.7.8 requires monitoring environmental conditions, lightning protection, and siting/protection measures that can enable recovery of equipment and some data after certain physical/environmental destruction events, but does not address logical data overwriting, deletion of cloud objects/VMs, or forensic irrecoverability from malware-driven destruction.
- T1495prevents — A.7.8 siting/protection guidelines (physical separation, environmental controls, lightning/emanation protection, access minimization) stop many physical vectors that could reach and corrupt firmware, but leave remote/software-only paths (e.g. malware on Linux/Windows) untouched.
- T1561.001recovers — A.7.8's environmental and physical protection (lightning, power filtering, temperature/humidity monitoring, siting to avoid damage) plus explicit backup-like recovery considerations in related guidance enable partial restoration of wiped systems after the destructive technique has run, but do not address the core disk-overwrite mechanism or network propagation.
- T1561.002recovers — A.7.8 requires backup/recovery-enabling siting, environmental protection, lightning safeguards and physical separation that enable restoration of wiped systems from unaffected or protected assets; the named remainder is the on-system structures themselves (no on-box redundancy is required by this clause).
- T1669prevents — A.7.8 siting/protection guidelines (a,b,c,h,i) directly constrain physical proximity and emanation risks that T1669 relies on for close-access Wi-Fi discovery and connection, but leave remote/dual-homed bridging, credentialed access to secured networks, and post-connection sniffing untouched.
Prevented OWASP Web Top 10 (2025) risks (1)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A01mitigates — A.7.8's physical siting, separation, viewing-angle positioning, emanation shielding and environmental protections bound the blast radius or consequence of some realized access-control failures (e.g. shoulder-surfing, physical theft of a session, EM leakage of auth tokens) but do not address the logical authorization-decision defects that dominate the A01 class.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.